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Security S3 

a! 

O when if mmes fo~ rTistnnrer "security/ no one is- nwe serious than 
O *i©s^^^.vis^ v '^e ; -*»a^--<te^R«^-^««' tbe--s3*5est-3n^ most error- free 
ULI systems around; To double check our security, we engaged ^ 
gj PriceWaterhouseCoopers as independent security auditors to give us a 
dean bill of health. Our policy is to conduct regular third-party audits of 
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— ! our serrifTtv rFy errsrrre rhaf-OTfr-stand^rds never siin. 

^ ' o 

We'ii walk you through our security., section by section, to let you know 
fl— how wfrrer nrntFtfi nor vorr The rtFTx1t^r?rrt vTstt ^n^ires that von are: 

CO 
UJ 

CD Protected against somebody stealing your personal data 

v Protected against electronic eavesdropping 
^• Protected against intercepted email 

;> Protected against hackers using your stolen credit card numbers 
' Protected against failed security 



Protected against somebody stealing your personal data ,4* 

Your private account information is Stored on an isolated Ne^tCarri Visa 
-computer ■eatte^'ff"Gff5+orn-er Ti imr 1 1 iriiJon ^erver. This server is 
carefully protected both physically and electronically. 

Physically, the server is stored in a highly secure building maintained 
by Exodus Communications Inc. , whose mission is to provide the 
highest degree of security for Internet applications. Key features of 
Exodus security: 

v/ Fire Suppression System - State-of-the-art gas-based fire 

prutectiarr system, separate fire Zuiies beiuw trie fioor and above the 
rafltn^: ^nreU^i^ s ^mnrs; arr^ automatic local fire 

de^artme^t ii^iftcation 

Facility Security System - Motion sensors, secured access, video 

CcrtT i cfer bUF y ei ii erf rutr , i^trCii Hi-y L?ftrtj Cif i -dirirf fi , otsd 24 X 7 automatic — ■ 

toCcrt" rrntlce department rtntif i ratio A 



• NexfCara Visa 



rage zoit 



refMHitft oeuf'ty djrMeni - it a / i_oiu K>cy i_usi.umci cn_ce:>;> iu 

Int@fn€c Dots Centers, monitoring,. 5ffd 24rX 7 or~ sits personnel 
Server Cage - Our server ts locked in a steel wire cage inside the 

SsCU fed ExodliS building 



El&citomcauYr youc private aixauflt information is NOT directly 

corrected to the Internet It sits behind; .'a fTrewatH '.The firewall ensures JJJ 

that the sensitive Information stored on the customer server is not — i 

avattabie ta unaiitoorizeftcorL^^ messages ^p? 
from ajj£iHffized:cuJnptifeers tfcrcaiuJi^ The firewatt we are using is a 

recognized industry standards and exceeds the standards set by the 3^ 
International Computer Security AssodationQCSA), a leading industry 

authority an the issue of Internet security. fjp 

_j Protected against electronic eavesdropping ror 

(30 You communicate with NextCard Visa through your computer's web >J 

^ hmwser. Ynrrr browsei' is a~i_xil:k-c» nfe'Ce'Of'our security infrastructure- Cm>* 

^ We only support browsers that use Secure Sockets i ayer (SSi ) 3 0 or 

2> hinher. 

^ Ym.fr frrnwser-wtfr r^^ SO you do 

UJ not have to take any extra steps to be protected- Tn fact,- before you 

GO foutrror fi lltnA At i ripg m^ f .io n: onr-server rfrecksr to make sure you're 
ijsi no one of the ^ooro^^6 browsers. 
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SSr .3^0; provides: profescSart^aifist electro^ eavesdropping through : 



%. Serv&e AuffienitcaUon - Secure SQ€feets.Layer 3.0 provides a 
way far you, to: verify tftafc yaff am. m €att tagging - an to the 
Efrexteard: visa server and; tsstra site tttarisiirnpersonati ng our 
seraer~ E^a£e:yau La server sends 

E4extCar4: Visa's p^ lets 
you verify the icteiikity of a ^ ser^erruy view^r^ifre" site's Certificate. 
A Certificate is a way gk associating a pubtic key to a name. You 
can. be sure thakyarr are tagged; arc ta the NextCar cf Visa server by 
viewi^om^GeFtEfic^efe when you're 

on th^Hrstpage af we orffee apptB^tion ar login screen. 

2. B&is-Mis&Ypimii^- QSrceSSt t^a^auttieriScateu tne server, your 
Dmw-see- a&^QA^serveFwig; estabtish; a secret symmetric key. The 
symmetric key/ aitaws yoar browser atgfc q^^seryer to exchange 
eas^ptetdata. The symmetric key/ is v^cf for a single session 
oofy^. It yeu fesg-oui: and; later (siroe ba^ : ta -RextCa rd Vi sa , your 
browsee our server wM m^&aSM a different symmetric key 
aut5fflae£a^ T^,syRTffiieW^ all of your 

r-nmmt frifV-af i>\r»e iA/ifh MovfParH \/ica 

X MBSsmffmM^trenticsti&&Cs^ - data; encryption in place, 
ag_ftH£si4£-par^ga^ but they 
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tampering, SSL uses a message authentication code (MAC). A 
MACrs a. piece of data tharr^ computed, using pieces of the 
symmetric key and the message itself. Your browser always ^ 
checks the mac before" interpreting a message from our server, if cn 
the message was scrambled by a hacker, the mac would not T/ 
correctly compute and your browser wilt alert you of possible ^ 
security hazards. The chances of someone scrambling a message ^ 
O anef then guessing the correct WACare pretty slim: about l in 

^ lB f 44& f 744 f 073 r 7m r 5Sl r &l& under TZ8"-bit encryption. 

UJ 

rn 

Protected against intercepted email T s P (("") 

^ E^ma+f- fe-a- great way to pass messages, put it is not a secure ,Q 
> communication channel Here at WextCard Visa , aH customer messag es -*© 
^ travei t^roug^-5ecureisiait(sFn-) r our secured, wetx-fijased communication 
£JJ system, Each of- our customers- has -a. personal SecureMair(sm) box that 
UJ is-eastfy -aceessifcte witnin ouc oistomer service website. And because 
^ S£cureMait(sro> is-entireiy web-teased, there's nq need to Team a new 
emaif program or download additional software. Seeu reMa i I (sm ) uses 
SSL 3.0 1& protect aR conftderitlar communication. 

Protected against hackers using your stolen credit card numbers^ 

in the wrong hands, technology has a way of distorting reality. For 
example, suppose you buy something wFtfr your fsextCard Visa from an 
Internet merchant who turns out not to be a merchant, but a clever 
thief. The merchant website rooked" f+fce a fegiftmate business and you 
took all the right precautions. But still, the hacker got your credit card 
number. 

it is FmpossFbfe to guarantee that an- internet thie^will never get your 
NextCard visa number, but we DO guarantee that you will not have to 
pay- for any- charges he rings up. 

Wepe^Sretff iQQ^ Sa^IateFR^Sbo^/mff Pte^ge^T ^Ne will cover 
tne full cost of" any fraud against your account that "arises from your 
usage of a Next Card visa over the Internet. Shop online risk FREE and 
rest assured that you wiW not be r^d responsibte for fraudulent 
charges- to- your :f$extO^VFsa4fteufredt>y- someone else. 



Protected against failed security 

Technology moves forward at a rapid pace. The thieves get smarter, 
and so d©- me-secarity -systems; -Wa matter -what happens, you are 
always protected against security breaches with our iGO% Safe 
ImeFfmt Shopping Piedge sm . 
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